# AI project risk record — editable Markdown template

OpenMax editorial template, 2026-09-04. Copy one record per risk. Fifteen logical groups, not fifteen spreadsheet columns. No macros, automatic scoring, legal approval or verified product integration. Have qualified owners approve the method before operational use.

Register agreement: define scope, allowed actions, affected users, assessment horizon, evidence storage/access, scoring policy and authority before filling records. Keep source material restricted where necessary. Unknown is not Low. A target is not current evidence. Retain accepted risks and closure history.

## 1. ID and workflow
- Risk ID: ___
- Title and workflow boundary: ___
- System/configuration version and exclusions: ___

## 2. Risk statement
- Cause → uncertain event → consequence: ___
- Related risks, issues or assumptions: ___

## 3. Category and people
- Primary/secondary category: ___
- Affected groups and consequences: ___

## 4. Evidence
- Source ID, version, date and exact locator: ___
- What it supports and what remains uncertain: ___
- Approved access location/restrictions: ___

## 5. Horizon and assumptions
- Period, volume, users and operating conditions: ___
- Material assumptions and verification owner: ___
- Change that requires reassessment: ___

## 6. Inherent assessment
- Hypothetical controls excluded, or reason not assessed: ___
- Likelihood, impact, priority and rationale: ___
- Assessor, date and policy version: ___

## 7. Existing controls
- Control IDs, coverage and responsible parties: ___
- Evidence dates and known bypass/failure conditions: ___

## 8. Current assessment
- Likelihood / impact / priority, or Unassessed: ___
- Rationale and evidence confidence: ___
- Assessor, date and scoring-policy version: ___

## 9. Response
- Proposed strategy and exact workflow change: ___
- Remaining exposure, alternatives and new risks: ___

## 10. Accountable owner
- Risk owner and confirmation: ___
- Escalation route and separate acceptance authority: ___

## 11. Actions — repeat for each action
- Action ID and deliverable: ___
- Action owner and due timestamp/time zone: ___
- State, completion date and completion evidence: ___
- Deadline-change reason and approval history: ___

## 12. Target
- Target likelihood / impact / priority: ___
- Assumptions, planned scope and required validation: ___

## 13. Validation and reassessment
- Test conditions, version and evidence locator: ___
- Result: Not run / Passed within scope / Failed / Inconclusive: ___
- Reviewer, date and limitations: ___
- Reassessed residual risk and rationale, or not established: ___

## 14. Acceptance
- Decision maker, authority and decision-record ID: ___
- Accepted scope, rationale and restrictions: ___
- Effective date, expiry and review conditions: ___

## 15. Lifecycle and review
- State: Active / Accepted with conditions / Closed for defined exposure: ___
- Next review and event-driven triggers: ___
- Assessment and decision change history: ___
- Closure reason, evidence, approver and reopening trigger: ___

Before sharing: verify scope, source access and dates; distinguish an open action from a current risk; separate implemented from effective; never treat a blank or target as verified current risk. Do not include real sensitive payloads in an unrestricted copy.
